Mind Architecture Group
Back to mindarchitecturegroup.com
Legal · v0.1 · Last updated 5 August 2026

Data Processing Agreement

GDPR Article 28 controller-to-processor template, ready for counter-signature with Mind Architecture Group.

How to use this template

Definitions

Subject matter and duration of processing

Categories of data and data subjects

Documented instructions and prohibited processing

Confidentiality (Art. 28(3)(b))

Security of processing (Art. 32)

Sub-processors (Art. 28(2) and 28(4))

Assistance with data subject rights (Art. 28(3)(e))

Security incident notification (Art. 33(2))

Return or deletion at end of processing (Art. 28(3)(g))

Audits and inspections (Art. 28(3)(h))

Liability

Governing law and order of precedence

Annex A — Schedule of Processing

Annex B — Sub-processor list

Signatures

Plain-English disclaimer.This document is a working v0.1 of our data processing agreement. It is written to be readable, not lawyer-proof. Before we rely on it for any actual legal commitment — a client contract, a regulator submission, a procurement response — it will be reviewed by a qualified lawyer in the relevant jurisdiction. Anything that looks like a binding commitment here is a placeholder until that review is on file.